|
| 1 | +Yubico Device Attestation CA |
| 2 | +============================ |
| 3 | + |
| 4 | +Last Update: 2025-02-03 |
| 5 | + |
| 6 | +Yubico manufactures security keys that contain device attestation |
| 7 | +certificates signed by a Yubico CA. This file contains the CA |
| 8 | +certificates that Relying Parties (RP) need to configure their software |
| 9 | +with in order to verify FIDO2, U2F, OpenPGP, PIV and Secure Domain |
| 10 | +attestation certificates of Yubico devices. |
| 11 | + |
| 12 | +This file has been signed with OpenPGP and you should verify the |
| 13 | +signature and the authenticity of the public key before trusting the |
| 14 | +content. The signature is located next to the file: |
| 15 | + |
| 16 | + https://developers.yubico.com/PKI/yubico-ca-certs.txt |
| 17 | + https://developers.yubico.com/PKI/yubico-ca-certs.txt.sig |
| 18 | + |
| 19 | +Signing keys and verification instructions are listed here: |
| 20 | + |
| 21 | + https://developers.yubico.com/Software_Projects/Software_Signing.html |
| 22 | + |
| 23 | +Each CA certificate in this file should, as required, be imported as a |
| 24 | +trusted certificate into your certificate path verification routine. |
| 25 | +Only one trusted certificate is needed for any one verification, but you |
| 26 | +may safely import them all to cover all cases. |
| 27 | + |
| 28 | +Intermediate CA certificates are available in a separate file, with all |
| 29 | +certificates concatenated. It does not have an OpenPGP signature since |
| 30 | +each certificate is already signed by the issuing CA. The file should be |
| 31 | +imported as an untrusted certificate store into your certificate path |
| 32 | +verification routine: |
| 33 | + |
| 34 | + https://developers.yubico.com/PKI/yubico-intermediate.pem |
| 35 | + |
| 36 | +For example, use a command like the following to verify a YubiKey |
| 37 | +attestation certificate in the file "yubikey-attestation.pem" using |
| 38 | +OpenSSL: |
| 39 | + |
| 40 | + openssl verify -trusted yubico-fido-ca-1.pem |
| 41 | + -trusted yubico-piv-ca-1.pem |
| 42 | + -trusted yubico-opgp-ca-1.pem |
| 43 | + -trusted yubico-fido-ca-2.pem |
| 44 | + -trusted yubico-ca-1.pem |
| 45 | + -untrusted 'https://developers.yubico.com/PKI/yubico-intermediate.pem' |
| 46 | + yubikey-attestation.pem |
| 47 | + |
| 48 | +With OpenSSL you may also use this file directly as a source of trusted |
| 49 | +certificates: |
| 50 | + |
| 51 | + openssl verify -trusted yubico-ca-certs.txt |
| 52 | + -untrusted 'https://developers.yubico.com/PKI/yubico-intermediate.pem' |
| 53 | + yubikey-attestation.pem |
| 54 | + |
| 55 | +We will update this file and the intermediate CAs file from time to time |
| 56 | +when we publish more CA certificates. |
| 57 | + |
| 58 | + |
| 59 | +Name: Yubico U2F Root CA Serial 457200631 |
| 60 | +Issued: 2014-08-01 |
| 61 | +Address: https://developers.yubico.com/PKI/yubico-fido-ca-1.pem |
| 62 | + https://developers.yubico.com/PKI/yubico-fido-ca-1.pem.sig |
| 63 | + |
| 64 | +-----BEGIN CERTIFICATE----- |
| 65 | +MIIDHjCCAgagAwIBAgIEG0BT9zANBgkqhkiG9w0BAQsFADAuMSwwKgYDVQQDEyNZ |
| 66 | +dWJpY28gVTJGIFJvb3QgQ0EgU2VyaWFsIDQ1NzIwMDYzMTAgFw0xNDA4MDEwMDAw |
| 67 | +MDBaGA8yMDUwMDkwNDAwMDAwMFowLjEsMCoGA1UEAxMjWXViaWNvIFUyRiBSb290 |
| 68 | +IENBIFNlcmlhbCA0NTcyMDA2MzEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK |
| 69 | +AoIBAQC/jwYuhBVlqaiYWEMsrWFisgJ+PtM91eSrpI4TK7U53mwCIawSDHy8vUmk |
| 70 | +5N2KAj9abvT9NP5SMS1hQi3usxoYGonXQgfO6ZXyUA9a+KAkqdFnBnlyugSeCOep |
| 71 | +8EdZFfsaRFtMjkwz5Gcz2Py4vIYvCdMHPtwaz0bVuzneueIEz6TnQjE63Rdt2zbw |
| 72 | +nebwTG5ZybeWSwbzy+BJ34ZHcUhPAY89yJQXuE0IzMZFcEBbPNRbWECRKgjq//qT |
| 73 | +9nmDOFVlSRCt2wiqPSzluwn+v+suQEBsUjTGMEd25tKXXTkNW21wIWbxeSyUoTXw |
| 74 | +LvGS6xlwQSgNpk2qXYwf8iXg7VWZAgMBAAGjQjBAMB0GA1UdDgQWBBQgIvz0bNGJ |
| 75 | +hjgpToksyKpP9xv9oDAPBgNVHRMECDAGAQH/AgEAMA4GA1UdDwEB/wQEAwIBBjAN |
| 76 | +BgkqhkiG9w0BAQsFAAOCAQEAjvjuOMDSa+JXFCLyBKsycXtBVZsJ4Ue3LbaEsPY4 |
| 77 | +MYN/hIQ5ZM5p7EjfcnMG4CtYkNsfNHc0AhBLdq45rnT87q/6O3vUEtNMafbhU6kt |
| 78 | +hX7Y+9XFN9NpmYxr+ekVY5xOxi8h9JDIgoMP4VB1uS0aunL1IGqrNooL9mmFnL2k |
| 79 | +LVVee6/VR6C5+KSTCMCWppMuJIZII2v9o4dkoZ8Y7QRjQlLfYzd3qGtKbw7xaF1U |
| 80 | +sG/5xUb/Btwb2X2g4InpiB/yt/3CpQXpiWX/K4mBvUKiGn05ZsqeY1gx4g0xLBqc |
| 81 | +U9psmyPzK+Vsgw2jeRQ5JlKDyqE0hebfC1tvFu0CCrJFcw== |
| 82 | +-----END CERTIFICATE----- |
| 83 | + |
| 84 | + |
| 85 | +Name: Yubico PIV Root CA Serial 263751 |
| 86 | +Issued: 2016-03-14 |
| 87 | +Address: https://developers.yubico.com/PKI/yubico-piv-ca-1.pem |
| 88 | + https://developers.yubico.com/PKI/yubico-piv-ca-1.pem.sig |
| 89 | + |
| 90 | +-----BEGIN CERTIFICATE----- |
| 91 | +MIIDFzCCAf+gAwIBAgIDBAZHMA0GCSqGSIb3DQEBCwUAMCsxKTAnBgNVBAMMIFl1 |
| 92 | +YmljbyBQSVYgUm9vdCBDQSBTZXJpYWwgMjYzNzUxMCAXDTE2MDMxNDAwMDAwMFoY |
| 93 | +DzIwNTIwNDE3MDAwMDAwWjArMSkwJwYDVQQDDCBZdWJpY28gUElWIFJvb3QgQ0Eg |
| 94 | +U2VyaWFsIDI2Mzc1MTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAMN2 |
| 95 | +cMTNR6YCdcTFRxuPy31PabRn5m6pJ+nSE0HRWpoaM8fc8wHC+Tmb98jmNvhWNE2E |
| 96 | +ilU85uYKfEFP9d6Q2GmytqBnxZsAa3KqZiCCx2LwQ4iYEOb1llgotVr/whEpdVOq |
| 97 | +joU0P5e1j1y7OfwOvky/+AXIN/9Xp0VFlYRk2tQ9GcdYKDmqU+db9iKwpAzid4oH |
| 98 | +BVLIhmD3pvkWaRA2H3DA9t7H/HNq5v3OiO1jyLZeKqZoMbPObrxqDg+9fOdShzgf |
| 99 | +wCqgT3XVmTeiwvBSTctyi9mHQfYd2DwkaqxRnLbNVyK9zl+DzjSGp9IhVPiVtGet |
| 100 | +X02dxhQnGS7K6BO0Qe8CAwEAAaNCMEAwHQYDVR0OBBYEFMpfyvLEojGc6SJf8ez0 |
| 101 | +1d8Cv4O/MA8GA1UdEwQIMAYBAf8CAQEwDgYDVR0PAQH/BAQDAgEGMA0GCSqGSIb3 |
| 102 | +DQEBCwUAA4IBAQBc7Ih8Bc1fkC+FyN1fhjWioBCMr3vjneh7MLbA6kSoyWF70N3s |
| 103 | +XhbXvT4eRh0hvxqvMZNjPU/VlRn6gLVtoEikDLrYFXN6Hh6Wmyy1GTnspnOvMvz2 |
| 104 | +lLKuym9KYdYLDgnj3BeAvzIhVzzYSeU77/Cupofj093OuAswW0jYvXsGTyix6B3d |
| 105 | +bW5yWvyS9zNXaqGaUmP3U9/b6DlHdDogMLu3VLpBB9bm5bjaKWWJYgWltCVgUbFq |
| 106 | +Fqyi4+JE014cSgR57Jcu3dZiehB6UtAPgad9L5cNvua/IWRmm+ANy3O2LH++Pyl8 |
| 107 | +SREzU8onbBsjMg9QDiSf5oJLKvd/Ren+zGY7 |
| 108 | +-----END CERTIFICATE----- |
| 109 | + |
| 110 | + |
| 111 | +Name: Yubico OpenPGP Attestation CA |
| 112 | +Issued: 2019-08-01 |
| 113 | +Address: https://developers.yubico.com/PKI/yubico-opgp-ca-1.pem |
| 114 | + https://developers.yubico.com/PKI/yubico-opgp-ca-1.pem.sig |
| 115 | + |
| 116 | +-----BEGIN CERTIFICATE----- |
| 117 | +MIIDOTCCAiGgAwIBAgIJAN0XtOvBoi4ZMA0GCSqGSIb3DQEBCwUAMCgxJjAkBgNV |
| 118 | +BAMMHVl1YmljbyBPcGVuUEdQIEF0dGVzdGF0aW9uIENBMB4XDTE5MDgwMTAwMDAw |
| 119 | +MFoXDTQ2MTIxNzAwMDAwMFowKDEmMCQGA1UEAwwdWXViaWNvIE9wZW5QR1AgQXR0 |
| 120 | +ZXN0YXRpb24gQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQClkKck |
| 121 | ++NEH+iSVLjbOvvreMlvkK4DZ7aETLusDfkEDy5+cv8SHtKSVcYfKhkST1l/5kbyx |
| 122 | +WAnxLRr+aYP52830qkDfYY1OE/IQG76BdWaGZJuMU4cdUPQR21Y7JB+ELHNMQHav |
| 123 | +3CmregKVqIRB6vgwWq/6AM37VKqKNTsBUmrAyihX/vY/kS3L1cP/NCPhUC9Gqab2 |
| 124 | +zohxXansjz92+4/dbN1cKDSGI8kVmoLpLbCf/CqGE4lWen0HxMCo/zIZo0nlGS7G |
| 125 | +rEAqN+PRRwiemBZhwBzeYiCLkh7qaqO4O1eWCNLjkJeLwIZ/uyRTESbaFoXOxqFp |
| 126 | +FjIyEjMYIdRXfaHVAgMBAAGjZjBkMB0GA1UdDgQWBBT7/MlvyfSnaal2RJH3cc8m |
| 127 | +ZS4SSjAfBgNVHSMEGDAWgBT7/MlvyfSnaal2RJH3cc8mZS4SSjASBgNVHRMBAf8E |
| 128 | +CDAGAQH/AgEBMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOCAQEAK+TP |
| 129 | +HgYNIFTy+2PXpxmPVnNOcJRcVykAxaLJAAxey2BXy9xmU7lzHbl2x23Lw3kH7Crr |
| 130 | +RqG67WGcwSZzvWWEcbq4zmX3vnu3FOFlqKFhU164tod4cXz1JGsTgfXaPRvoKJAo |
| 131 | +XMotYH/u2UY/K8jmqycgEyHAFc9wx1v/q0H6p4WgbXLu2oBzRodHokgK/6EbIbR+ |
| 132 | +Jok3xJ+5haGcMCCz2A8RBah4dxPDNeaz3tSkAjrtwLANV79hAZv2g9CZX6z0H2Zy |
| 133 | +HhK6CLTg2MfwT0NxS3Am76k2opXSqbk8k5nnNFSYFuvgxunQxUOB+3M+gWHmVTh8 |
| 134 | +7yaamyNndwmhhIAgeA== |
| 135 | +-----END CERTIFICATE----- |
| 136 | + |
| 137 | + |
| 138 | +Name: Yubico FIDO Root CA Serial 450203556 |
| 139 | +Issued: 2024-05-01 |
| 140 | +Address: https://developers.yubico.com/PKI/yubico-fido-ca-2.pem |
| 141 | + https://developers.yubico.com/PKI/yubico-fido-ca-2.pem.sig |
| 142 | + |
| 143 | +-----BEGIN CERTIFICATE----- |
| 144 | +MIIDMzCCAhugAwIBAgIUSOEjTf//yqRfPW7Qq8qtIyCrAg8wDQYJKoZIhvcNAQEL |
| 145 | +BQAwLzEtMCsGA1UEAwwkWXViaWNvIEZJRE8gUm9vdCBDQSBTZXJpYWwgNDUwMjAz |
| 146 | +NTU2MCAXDTI0MDUwMTAwMDAwMFoYDzIwNjAwNDMwMDAwMDAwWjAvMS0wKwYDVQQD |
| 147 | +DCRZdWJpY28gRklETyBSb290IENBIFNlcmlhbCA0NTAyMDM1NTYwggEiMA0GCSqG |
| 148 | +SIb3DQEBAQUAA4IBDwAwggEKAoIBAQCdvl27w2gu1fPXeEFbIdqx0BalvVDVWrQP |
| 149 | +J7HqviuEtZHlxSLxSFtcXpTolvLvof8f4tMerQTkVGzcmYzm1EBT4IJuMmoEqfkE |
| 150 | +EhWpsADMFrjZkqlZY9EqxQzLoVEEonE5oGxSdVCxCcLIackpyR/CCXvj1Bt/hTgE |
| 151 | +9hTlF4pRqxMkx3plF7y8dDZlRHWs7vbnhmBCGeI0ZPEQ6nl2mCg2r74adF2u6K9r |
| 152 | +rLfhBC3QLE8EPrgqUsI+hkuq2tK4M2SMOp8uUVVkqUeu3h0kr3WVI0W02pkgrOgi |
| 153 | +FKLFNkSrbYhdjMBDj5izmqfc9xJRKoDX612qd8ZGVHpT5AYFX+1hAgMBAAGjRTBD |
| 154 | +MB0GA1UdDgQWBBTZyU5DiQ/a2UEgE7qBK0zhIsRNRjASBgNVHRMBAf8ECDAGAQH/ |
| 155 | +AgEAMA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOCAQEAXvnB4SLuUJfY |
| 156 | +MSVGAhssL/SmWli3FSccgxydvKlACcidIIWKQqa3q/QSUEQzC9DgEfMgr7iC1BkT |
| 157 | +ZbILboV6UZ5knNsvjEZWuMeogJ8tgZs1hVvKwZizwJ+mEcmsjhIrBYuoL1T6yrOJ |
| 158 | +vKFg1jv+Cy4ZwA9Bpk/V3UOir1VyK8dCtyHu6vfosotAdYx8FAuR243gRTMV6Jx8 |
| 159 | +Jdig2JDIAQMlzVeDpSUHX/K2HXRHxHwfgjbgUjjBu/72r8OfehyhzHXI3K8CFFdf |
| 160 | +lO+8nEOJK3y8F1ivgS5uN/8SmcYw/STQYwhrxPuwz3nP8baMum4BB2nnYmpB60sX |
| 161 | +3bl5k8QUSw== |
| 162 | +-----END CERTIFICATE----- |
| 163 | + |
| 164 | + |
| 165 | +Name: Yubico Attestation Root 1 |
| 166 | +Issued: 2024-12-01 |
| 167 | +Address: https://developers.yubico.com/PKI/yubico-ca-1.pem |
| 168 | + https://developers.yubico.com/PKI/yubico-ca-1.pem.sig |
| 169 | + |
| 170 | +-----BEGIN CERTIFICATE----- |
| 171 | +MIIDPjCCAiagAwIBAgIUXzeiEDJEOTt14F5n0o6Zf/bBwiUwDQYJKoZIhvcNAQEN |
| 172 | +BQAwJDEiMCAGA1UEAwwZWXViaWNvIEF0dGVzdGF0aW9uIFJvb3QgMTAgFw0yNDEy |
| 173 | +MDEwMDAwMDBaGA85OTk5MTIzMTIzNTk1OVowJDEiMCAGA1UEAwwZWXViaWNvIEF0 |
| 174 | +dGVzdGF0aW9uIFJvb3QgMTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEB |
| 175 | +AMZ6/TxM8rIT+EaoPvG81ontMOo/2mQ2RBwJHS0QZcxVaNXvl12LUhBZ5LmiBScI |
| 176 | +Zd1Rnx1od585h+/dhK7hEm7JAALkKKts1fO53KGNLZujz5h3wGncr4hyKF0G74b/ |
| 177 | +U3K9hE5mGND6zqYchCRAHfrYMYRDF4YL0X4D5nGdxvppAy6nkEmtWmMnwO3i0TAu |
| 178 | +csrbE485HvGM4r0VpgVdJpvgQjiTJCTIq+D35hwtT8QDIv+nGvpcyi5wcIfCkzyC |
| 179 | +imJukhYy6KoqNMKQEdpNiSOvWyDMTMt1bwCvEzpw91u+msUt4rj0efnO9s0ZOwdw |
| 180 | +MRDnH4xgUl5ZLwrrPkfC1/0CAwEAAaNmMGQwHQYDVR0OBBYEFNLu71oijTptXCOX |
| 181 | +PfKF1SbxJXuSMB8GA1UdIwQYMBaAFNLu71oijTptXCOXPfKF1SbxJXuSMBIGA1Ud |
| 182 | +EwEB/wQIMAYBAf8CAQMwDgYDVR0PAQH/BAQDAgGGMA0GCSqGSIb3DQEBDQUAA4IB |
| 183 | +AQC3IW/sgB9pZ8apJNjxuGoX+FkILks0wMNrdXL/coUvsrhzsvl6mePMrbGJByJ1 |
| 184 | +XnquB5sgcRENFxdQFma3mio8Upf1owM1ZreXrJ0mADG2BplqbJnxiyYa+R11reIF |
| 185 | +TWeIhMNcZKsDZrFAyPuFjCWSQvJmNWe9mFRYFgNhXJKkXIb5H1XgEDlwiedYRM7V |
| 186 | +olBNlld6pRFKlX8ust6OTMOeADl2xNF0m1LThSdeuXvDyC1g9+ILfz3S6OIYgc3i |
| 187 | +roRcFD354g7rKfu67qFAw9gC4yi0xBTPrY95rh4/HqaUYCA/L8ldRk6H7Xk35D+W |
| 188 | +Vpmq2Sh/xT5HiFuhf4wJb0bK |
| 189 | +-----END CERTIFICATE----- |
0 commit comments